Security Policy

How to report a vulnerability and what we promise in return, what protects the Service, and exactly what we will do if we are breached. It states what we actually have, and names what we do not.

In force from
Version
1.0
Issued by
OmniOS OÜ

1Reporting a vulnerability

Email [email protected]. Tell us what you found, where, and how to reproduce it. A proof of concept helps; a video is fine; a scanner report on its own usually is not.

Acknowledgement
Within 2 working days.
First assessment
Within 5 working days, with our view of severity and whether we are treating it as a vulnerability.
Fix target
Critical within 7 days, high within 30, medium within 90. If we will miss a target we tell you and say why.
Disclosure
Coordinated. We ask you to hold publication until a fix is deployed, and we will not stall — 90 days from your report is the outer limit, after which publish regardless.
Credit
We name you in the changelog if you want to be named, and stay quiet if you do not.

We do not run a paid bug bounty. We are a small company and would rather say that plainly than imply a reward we will not pay.

2Safe harbour for good-faith research

If you follow the rules below, we will not pursue legal action against you, and we will say so in writing to anyone who asks. We treat your research as authorised for the purposes of computer-misuse law and of our own Terms.

  • Test only against your own account and your own data. Do not access, modify or retain anyone else's.
  • Stop as soon as you have confirmed a vulnerability. Do not pivot deeper to see how far it goes.
  • If you access personal data by accident, stop, tell us immediately, and delete it. Do not keep a copy as proof.
  • No denial of service, no volumetric or stress testing, no spam, no social engineering of our people or our providers, and no physical attacks.
  • Do not use a finding to extract data, place trades, or gain paid entitlements you have not bought.
  • Give us reasonable time to fix it before you publish.

Break those and the safe harbour does not apply. In particular, an extortion demand attached to a report is not research, and we will treat it as what it is.

3How the Service is protected

AreaWhat we do
TransportTLS 1.2 or better everywhere, HSTS with a two-year max-age and preload, and a restrictive content security policy.
AuthenticationSalted password hashing with a modern key-derivation function; signed HttpOnly, Secure, SameSite=Strict session cookies with a 24-hour lifetime; OAuth with PKCE and single-use state nonces.
AuthorisationEntitlements checked server-side on every request. A client that asks for data above its plan is refused by the API, not hidden by the interface.
Data locationHosted in the European Union, in Frankfurt, Germany. See the sub-processors page for everything that sits outside it.
BackupsEncrypted, scheduled, and verified by restore drills rather than assumed to work.
Access controlProduction access limited to those who need it, over authenticated channels, with an append-only audit log.
Abuse resistancePer-plan rate limiting, anomaly detection on authentication, and a WAF in front of everything.
DependenciesAutomated vulnerability scanning, with security updates taking priority over feature work.
PaymentsCard data goes to Stripe directly. We never receive or store a full card number.

We hold no ISO 27001 or SOC 2 certification, and we do not imply one. If your procurement process needs a security questionnaire completed, write to [email protected] and we will answer it honestly.

4If we suffer a breach

We maintain a written incident response procedure. In an incident involving personal data:

  • We contain it first, then investigate scope, then notify. In that order.
  • Where the breach is likely to risk your rights and freedoms, we notify the Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate) within 72 hours of becoming aware of it, as Article 33 GDPR requires.
  • Where the risk to you is high, we tell you directly and without undue delay, in plain language: what happened, what data was involved, what we have done, and what you should do — Article 34 GDPR.
  • Business customers with a data processing agreement are notified without undue delay so they can meet their own obligations.
  • We publish a post-incident summary once the incident is closed. We would rather write that than have someone else write it for us.

We will not describe a breach as a "security incident affecting a limited number of accounts" when it is not, and we will not delay telling you in order to finish the investigation first.

5Your part

  • Use a unique password, or sign in with Google.
  • Treat API keys like passwords. Rotate one you have pasted anywhere public, immediately.
  • Tell us at [email protected] the moment you suspect your account is compromised.
  • Remember that we will never ask you for your password, and never ask you to move funds anywhere. Anyone who does is not us.

OmniOS OÜ never takes custody of crypto-assets and never asks for a private key or seed phrase, for any reason, ever.